Arbitrary SQL Command Execution in Views Module for Drupal

Arbitrary SQL Command Execution in Views Module for Drupal

CVE-2011-4113 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

Learn more about our Web Application Penetration Testing UK.